Windows .Key File Creation in Root Directory — Detection Rule

Detects the creation of a .key file in the root directory of the system drive. This activity was seen with various ransomware before performing encryption of files.

Read the full analysis on IntelFusions